Sceawere

Vulnerability Detail

CVE-2026-108863UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Katanemo Plano Unauthorized Envoy Access

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
Katanemo
Product
Plano
Attack Type
Missing Authentication for Critical Function
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Katanemo Plano through 0.4.37 contains a missing authentication vulnerability that allows unauthenticated network attackers to access the Envoy admin interface, which is bound to all host interfaces on port 9901. Attackers can request the /config_dump endpoint to read configured LLM provider API keys in plaintext from the WASM filter configuration.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-11T14:17:06.360Z",
  "pubdate": "2026-10-11T14:17:06.360Z",
  "executiveSummary": "Katanemo Plano versions through 0.4.37 are susceptible to a critical missing authentication vulnerability affecting the Envoy admin interface. The interface is improperly configured to bind to all host interfaces on port 9901, exposing sensitive internal configuration data to any unauthenticated network actor.\nThe primary risk involves the unauthorized extraction of LLM provider API keys stored in plaintext within the WASM filter configuration. Because the Envoy admin interface is exposed globally without authentication, attackers can remotely query the /config_dump endpoint to retrieve these credentials. Successful exploitation leads to a complete compromise of configured LLM provider integrations, potentially resulting in unauthorized resource consumption, data exfiltration, or financial impact associated with API usage. The vulnerability does not require prior authentication or specialized privileges, making it highly accessible to external network-adjacent attackers.",
  "technicalDetails": "The vulnerability resides in the network configuration of the Envoy proxy component integrated within Katanemo Plano. In affected versions (0.4.37 and earlier), the Envoy admin interface is bound to the wildcard address (0.0.0.0) on TCP port 9901, rather than being restricted to the loopback interface (127.0.0.1) or protected by access control lists (ACLs). This misconfiguration renders the administrative port accessible from any network segment that can route to the host, bypassing the intended security boundaries.\nThe attack flow begins with the reconnaissance of the target infrastructure to identify active TCP listeners on port 9901. Once the Envoy admin interface is identified, an unauthenticated attacker can interact directly with the administrative HTTP server. The core of the exploitation involves targeting the /config_dump endpoint, which serves as a diagnostic tool designed to return the full current configuration state of the Envoy proxy.\nWithin the context of Katanemo Plano, the WASM filter configurations utilized for LLM orchestration are included in the output generated by the /config_dump endpoint. These configurations contain hardcoded or plaintext API keys intended for authentication with third-party LLM providers. Because the admin interface lacks an authentication requirement or rate-limiting mechanism for this sensitive endpoint, the attacker can execute a simple HTTP GET request to receive the full configuration object.\nThe post-exploitation impact is severe, as the attacker effectively gains access to the same credentials used by the application to interact with LLM backends. By exfiltrating these keys, an attacker can impersonate the Katanemo Plano instance in interactions with the provider, leading to potential account hijacking, unauthorized billing, or the interception of proprietary prompts and data sent to the LLM service. The absence of authentication at the protocol level ensures that no logs or session tokens are required to complete the theft, simplifying the execution for automated scanning tools and remote adversaries alike."
}
CVE-2026-108863: Katanemo Plano Unauthorized Envoy Access (HIGH Severity, CVSS: 7.5) | Sceawere